Azure MFA for Enrollment in Intune and Azure AD Device registration explained

I have been working with setup of MFA required for enrollement in Intune abit lately and have discovered a couple of things that is not really explained well in the Intune console/documentation.

Enrollment of devices in Intune will in most cases also trigger a device registration in Azure AD. This registration in Azure AD can easily be connected to a MFA requirement by just configure your Azure AD to require MFA for device registration. But this does not apply to all scenarios, so in this blogpost I am going to go into each plattform and explain what happens during enrollment and how the MFA is triggered. I will also cover different options for enrollment of Windows 10 Mobile.  Continue reading

Single Sign-On to on-premises resources from Azure AD joined when Onprem

Azure AD Join was introduced in Windows 10 and allows a Windows 10 device to register with Azure Active Directory (Azure AD) and allows Azure AD users to sign-in to the device using their work credentials or more commonly know as their O365 credentials.

Users on these devices will enjoy Single Sign-On (SSO) to Office 365 or other SaaS applications.

The really cool part is that if this user is working within the corporate network the user can enjoy SSO to on-premises Integrated Windows Authentication based resources as well, provided the organization has enabled this functionality. Continue reading

Why and how you should register your Windows 10 Domain Joined PC’s with Azure AD

It has been a while since my last blogpost as I have been on parental leave with my 1 year old son. I have also got a new employment since then and are now working for Lumagate AS in Norway as a Senior Consultant. Over to the important stuff 🙂

Domain joining a PC has been the way for companies in a long time to make sure they have a common identity inside their network and control of the PCs in their network. This does not change with Windows 10. However new possibilities come to play when Azure AD becomes a part of the picture. Continue reading

Windows 10, Azure AD Join and SSO (Build 10162)

A while back I wrote a post regarding Azure AD Join or Connect to cloud that it was called in earlier build. Since then a lot of stuff has happened and I really feel the quality and usefullness of Azure AD Join is getting close to target.

So this post is gonna focus on the OOBE experience of a new users experience when logging into a new computer for the first time. I am sorry for the norwegian language in the screenshots I have made, but you will understand what they are about anyway 🙂 Continue reading